MGASA-2016-0418

Source
https://advisories.mageia.org/MGASA-2016-0418.html
Import Source
https://advisories.mageia.org/MGASA-2016-0418.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0418
Published
2016-12-11T22:44:05Z
Modified
2026-04-16T04:27:35.431747Z
Summary
Updated python-tornado package fixes security vulnerability
Details

A difference in cookie parsing between Tornado and web browsers (especially when combined with Google Analytics) could allow an attacker to set arbitrary cookies and bypass XSRF protection. The cookie parser has been rewritten to fix this attack.

References
Credits

Affected packages

Mageia:5 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/mageia/python-tornado?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.2-4.2.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2016-0418.json"